| 2.9.1 Ensure External Intelligence Extensions Is Disabled | AirWatch - CIS Apple iOS 18 Benchmark v2.0.0 L1 End User Owned | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| 3.10.1 Ensure External Intelligence Extensions Is Disabled | AirWatch - CIS Apple iPadOS 26 v1.0.0 L1 Institutionally Owned | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 3.10.1 Ensure External Intelligence Extensions Is Disabled | AirWatch - CIS Apple iOS 18 v2.0.0 L1 Institution Owned | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 3.10.1 Ensure External Intelligence Extensions Is Disabled | MobileIron - CIS Apple iOS 26 v1.0.0 L1 Institution Owned | MDM | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 7.17 AirDrop security considerations | CIS Apple macOS 10.12 L1 v1.2.0 | Unix | CONFIGURATION MANAGEMENT |
| ALMA-09-001120 - AlmaLinux OS 9 must automatically lock graphical user sessions after 10 minutes of inactivity. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-002990 - AlmaLinux OS 9 SSH client must be configured to use only encryption ciphers employing FIPS 140-3-validated cryptographic hash algorithms to protect the confidentiality of SSH client connections. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-003430 - AlmaLinux OS 9 must implement DOD-approved systemwide cryptographic policies to protect the confidentiality of SSH server connections. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-003870 - AlmaLinux OS 9 IP tunnels must use FIPS 140-3 approved cryptographic algorithms. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-004970 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| ALMA-09-006070 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect the files within /etc/sudoers.d/ | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| ALMA-09-007060 - AlmaLinux OS 9 must enable kernel parameters to enforce discretionary access control on hardlinks. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-007280 - AlmaLinux OS 9 must audit uses of the "execve" system call. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-007610 - AlmaLinux OS 9 must automatically lock the root account until the root account is released by an administrator when three unsuccessful logon attempts occur during a 15-minute time period. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-032030 - AlmaLinux OS 9 must require users to provide a password for privilege escalation. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-032140 - AlmaLinux OS 9 must not be configured to bypass password requirements for privilege escalation. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-032250 - AlmaLinux OS 9 must require reauthentication when using the "sudo" command. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL |
| ALMA-09-033460 - The pcscd socket on AlmaLinux OS 9 must be active. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | IDENTIFICATION AND AUTHENTICATION |
| ALMA-09-033680 - AlmaLinux OS 9 must implement certificate status checking for multifactor authentication. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | IDENTIFICATION AND AUTHENTICATION |
| ALMA-09-035000 - AlmaLinux OS 9 must prevent a user from overriding the disabling of the graphical user interface automount function. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | IDENTIFICATION AND AUTHENTICATION |
| ALMA-09-035660 - AlmaLinux OS 9 must disable account identifiers (individuals, groups, roles, and devices) after 35 days of inactivity. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | IDENTIFICATION AND AUTHENTICATION |
| ALMA-09-036760 - AlmaLinux OS 9 must require the change of at least four character classes when passwords are changed. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | IDENTIFICATION AND AUTHENTICATION |
| ALMA-09-037090 - AlmaLinux OS 9 must require the change of at least eight characters when passwords are changed. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | IDENTIFICATION AND AUTHENTICATION |
| ALMA-09-037200 - AlmaLinux OS 9 PAM must be configured to use a sufficient number of password hashing rounds. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | IDENTIFICATION AND AUTHENTICATION |
| ALMA-09-037970 - Passwords for existing users must have a 60-day maximum password lifetime restriction in /etc/shadow. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | IDENTIFICATION AND AUTHENTICATION |
| ALMA-09-038960 - AlmaLinux OS 9 must map the authenticated identity to the user or group account for PKI-based authentication. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | IDENTIFICATION AND AUTHENTICATION |
| ALMA-09-039290 - AlmaLinux 9 cryptographic policy must not be overridden. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| ALMA-09-041600 - AlmaLinux OS 9 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| ALMA-09-042370 - AlmaLinux OS 9 must protect against or limit the effects of denial-of-service (DoS) attacks by ensuring rate-limiting measures on impacted network interfaces are implemented. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| ALMA-09-043030 - AlmaLinux OS 9 must not allow users to override SSH environment variables. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| ALMA-09-043250 - AlmaLinux OS 9 wireless network adapters must be disabled. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| ALMA-09-043910 - AlmaLinux OS 9 /var/log directory must be group-owned by root. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| ALMA-09-044130 - AlmaLinux OS 9 /var/log/messages file must be owned by root. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| ALMA-09-044900 - AlmaLinux OS 9 must implement address space layout randomization (ASLR) to protect its memory from unauthorized code execution. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| ALMA-09-045450 - AlmaLinux OS 9 must routinely check the baseline configuration for unauthorized changes and notify the system administrator when anomalies in the operation of any security functions are discovered. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| ALMA-09-046770 - AlmaLinux OS 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /var/log/tallylog. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| ALMA-09-048420 - AlmaLinux OS 9 must generate audit records for any use of the "chcon" command. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| ALMA-09-050620 - AlmaLinux OS 9 must generate audit records for any use of the "ssh-keysign" command. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| ALMA-09-050950 - AlmaLinux OS 9 must generate audit records for any use of the "unix_chkpwd" command. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| ALMA-09-052380 - AlmaLinux OS 9 must take appropriate action when the internal event queue is full. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY |
| ALMA-09-053040 - AlmaLinux OS 9 must be configured to forward audit records via TCP to a different system or media from the system being audited via rsyslog. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY |
| ALMA-09-053150 - The rsyslog service on AlmaLinux OS 9 must be active. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY |
| ALMA-09-053480 - AlmaLinux OS 9 must take action when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY |
| ALMA-09-054140 - AlmaLinux OS 9 audit system must take appropriate action when the audit storage volume is full. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY |
| ALMA-09-054360 - AlmaLinux OS 9 audit system must make full use of the audit storage space. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY |
| ALMA-09-054470 - AlmaLinux OS 9 audit system must take appropriate action when the audit files have reached maximum size. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY |
| ALMA-09-054690 - AlmaLinux OS 9 must periodically flush audit records to disk to prevent the loss of audit records. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY |
| ALMA-09-055130 - The chronyd service must be enabled. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY |
| ALMA-09-056120 - AlmaLinux OS 9 audit logs must have 0600 permissions to prevent unauthorized read access. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY |
| ALMA-09-056340 - AlmaLinux OS 9 audit tools must be owned by root. | DISA Cloud Linux AlmaLinux OS 9 STIG v1r7 | Unix | AUDIT AND ACCOUNTABILITY |